Vulnerabilities exploitable today
376,337in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,713
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,372
- High8,705
- Medium6,723
- Low721
Filters
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2012-2737—30.0%
——9——CVE-2013-2777—30.0%
——9——CVE-2025-12335—30.0%
——9——CVE-2003-0794—30.0%
——9——CVE-2012-4453—30.0%
——9——CVE-2024-29934—30.0%
——9——CVE-2022-39863—30.0%
——9——CVE-2026-30930—30.0%
——9——CVE-2025-52429—30.0%
——9——CVE-2025-6694—30.0%
——9——CVE-2017-10744—30.0%
——9——CVE-2022-26326—30.0%
——9——CVE-2024-409297.1 HIG30.0%
——9In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: check n_ssids before accessing the ssids
In some versions of cfg80211, the ssids poinet might be a valid one even
though n_ssids is 0. Accessing the pointer in this case will cuase an
out-of-bound access. Fix this by checking n_ssids first.45dCVE-2017-10742—30.0%
——9——CVE-2017-14295—30.0%
——9——CVE-2025-53406—30.0%
——9——CVE-2025-2928—30.0%
——9——CVE-2023-29639—30.0%
——9——CVE-2024-39755—30.0%
——9——CVE-2023-22375—30.0%
——9——CVE-2025-12244—30.0%
——9——CVE-2026-40561—30.0%
——9——CVE-2025-12334—30.0%
——9——CVE-2026-727099.8 CRI30.0%
——9SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can bypass template-level authorization guards through direct HTTP requests to invoke actions such as editer_auteur, enabling arbitrary account password rewrites including administrator accounts and resulting in full account takeover.4dCVE-2017-14574—30.0%
——9——CVE-2023-42321—30.0%
——9——CVE-2026-580819.8 CRI30.0%
——9Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters.
An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules.18dCVE-2023-50017—30.0%
——9——CVE-2026-830467.1 HIG30.0%
——9Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).2dCVE-2022-42071—30.0%
——9——CVE-2025-12299—30.0%
——9——CVE-2026-659256.5 MED30.0%
——9A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.50dCVE-2026-920878.1 HIG30.0%
——9@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the relation "or" option together with the run "all" option and one entry is a nested array acting as an AND group, the group is evaluated in an order-dependent way: an earlier failing check is silently dropped and the group's result becomes the outcome of its last check. As a result, a request that satisfies only the last member of an AND group, for example an attacker who holds a valid API key but is not an administrator, is authorized instead of rejected, and a related order-dependent bypass affects the mirror configuration where the top-level relation is "and" and a nested group uses "or". The issue is fixed in @fastify/auth 5.1.1, and users should upgrade to 5.1.1 or later. As a workaround, omit the run "all" option where it is not required, order each AND group so its stricter check is evaluated last, or replace nested AND groups with an explicit top-level "and" composition.2dCVE-2026-7518—30.0%
——9——CVE-2026-13149—30.0%
——9brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.72dCVE-2008-3900—30.0%
——9——CVE-2006-0511—30.0%
——9——CVE-2017-10737—30.0%
——9——CVE-2026-162437.5 HIG30.0%
——9In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.38dCVE-2025-64702—30.0%
——9——